Swiss autism-support foundation Stiftung Autismuslink confirms data-theft cyberattack; INC Ransom claims it
Stiftung Autismuslink — a Bern-based foundation providing school, coaching and vocational-integration services to adolescents and young adults with autism — published a signed victim notice confirming a cyberattack: "Ende Juni wurde unsere IT-Infrastruktur Opfer eines Cyberangriffs. Nach aktueller Erkenntnis wurden grössere Datenmengen durch die Angreifer abgezogen und unser Server vorübergehend verschlüsselt" (end of June our IT infrastructure fell victim to a cyberattack; larger volumes of data were exfiltrated and our server temporarily encrypted) (Stiftung Autismuslink, 2026-07). The foundation states the irregularity was detected Monday 2026-06-29, the system was immediately isolated from the internet, an external IT provider (Infoguard) was engaged for forensics the same day, the relevant authorities were notified and a criminal complaint filed with the police. Backups were verified unaffected. The INC Ransom (Incransom) double-extortion group posted a leak-site claim against autismuslink.ch on 2026-07-24 consistent in victim identity and timeline (Ransomware.live, 2026-07-24) — a relatively rare case of same-day victim self-disclosure and leak-site claim converging.
The disclosure event (site notice plus leak-site claim) is what falls in this window; the underlying intrusion dates to late June. What makes it relevant beyond a single victim is the data class: per the foundation, affected material includes service agreements with the Swiss disability insurance (IV) and a cantonal education/culture directorate (BKD), teacher contracts, doctors' certificates and the complete client dossier archive 2016-2023 for minors and young adults.
Ende Juni wurde unsere IT-Infrastruktur Opfer eines Cyberangriffs. Nach aktueller Erkenntnis wurden grössere Datenmengen durch die Angreifer abgezogen und unser Server vorübergehend verschlüsselt.
Backupsysteme der Stiftung Autismuslink wurden kontrolliert und sind nicht vom Angriff betroffen.
ATT&CK mapping
2 techniques mapped from the cited reporting · MITRE ATT&CK v19.1
Collection TA0009
T1005Data from Local System
Adversaries may search local system sources, such as file systems, configuration files, local databases, virtual machine files, or process memory, to find files of interest and sensitive data prior to Exfiltration.
Impact TA0040
T1486Data Encrypted for Impact
Adversaries may encrypt data on target systems or on large numbers of systems in a network to interrupt availability to system and network resources. They can attempt to render stored data inaccessible by encrypting files or data on local and remote drives and withholding access to a decryption key. This may be done in order to extract monetary compensation from a victim in exchange for decryption or a decryption key (ransomware) or to render data permanently inaccessible in cases where the key is not saved or transmitted.
Sources
AI-generated · no human review · this permalink is the shareable record for the finding · verify operationally critical claims against the linked primary source.